Go Back   vb.org Archive > Community Central > Community Lounge
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 12-08-2012, 12:13 AM
Pablo18
Guest
 
Posts: n/a
Default vBulletin very easy to hacked ?

What's going on here...?

In last few days hackers party a lot with vBulletin forum :

***link removed***

I don't care with their reason, but the fact he can hacked few vBulletin forum easily made me think....how weak security in vBulletin. The situation is the fact.

Any opinion...? or providing security patch...?
  #2  
Old 12-08-2012, 12:35 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Pablo18 View Post
.how weak security in vBulletin.
As weak as the owner/installer/admin makes it.
  #3  
Old 12-08-2012, 01:05 AM
Pablo18
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Max Taxable View Post
As weak as the owner/installer/admin makes it.
Oh really...? Are you sure...? I don't think so.

This hackers clearly using the bugs in sytem, don't always blame owner/installer/admin.

The story will be different if security patch always update..
  #4  
Old 12-08-2012, 01:10 AM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

How do you know how it's being done?
2 благодарности(ей) от:
Amaury, Max Taxable
  #5  
Old 12-08-2012, 01:37 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Pablo18 View Post
Oh really...? Are you sure...? I don't think so.

This hackers clearly using the bugs in sytem, don't always blame owner/installer/admin.

The story will be different if security patch always update..
I've had vBulletin installations for many years, going back at least to 2004. Never been "hacked," cracked, defaced, anything.

There's not any web pages that don't have some kind of exploit in them, vBulletin's not alone there.
Quote:
The story will be different if security patch always update..
Which, does depend on the owner/admin to apply in a timely manner.
3 благодарности(ей) от:
Amaury, doctorsexy, OldSchoolDSL
  #6  
Old 12-08-2012, 12:59 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Pablo18 View Post
....how weak security in vBulletin.
It isnt. There are no known exploits at this time.

Quote:
Originally Posted by Pablo18 View Post
The situation is the fact.
What facts ?
Do you have solid proof on how they were hacked ?

No ? then you have no "facts".
2 благодарности(ей) от:
OldSchoolDSL, TTayfun
  #7  
Old 12-08-2012, 01:40 PM
trackpads's Avatar
trackpads trackpads is offline
 
Join Date: Aug 2003
Location: Armyville
Posts: 1,074
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Agreed with Paul.

My 2 cents. You are always at risk of something bad happening. That is the risk you take. You mitigate risk by backing up/testing backups and doing your utmost to secure your site AND your server.

Some of these hacks could have been done at the server level, not just software. You just don't know. Every major hosting provider has had successful attacks. You learn, adapt and move on.

In the case with IQ69, I found on their twitter feed, that group that hacked them is claiming to have all 50GB their data. To get that kind of access you need console access. No one can sqldump 50GB from the phpmyadmin interface. Plus the files etc are not just available because you have a admin password. They have ftp access too.

a. NONE of your logins and passwords should be the same. If your ftp, cpanel, root, forum and others admin logins are all the same then you are screwing yourself.

b. Use secure server software with a provider that has the latest updates. Cpanel etc.

c. BACKUP!!!!!

d. BACKUP off site!!!!

Hope this helps,

-Jason Edwards, CISSP

--------------- Added [DATE]1354978181[/DATE] at [TIME]1354978181[/TIME] ---------------

Secondly,

Use a Firewall or Proxy service. Some attacks can be foiled by a good proxy. I use cloudflare and have found it to be usefull. Does require some tooling to get some Vbulletin mods to work but it has blocked massive amounts of malicious ip traffic from ever reaching my site. IT can also cache and do other improvements as well that will speed up your site.
  #8  
Old 12-08-2012, 04:20 PM
puertoblack2003's Avatar
puertoblack2003 puertoblack2003 is offline
 
Join Date: Aug 2005
Location: Philadelphia
Posts: 1,073
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

vbulletin has nothing to do with exploits. It's server side. I remember reading it somewhere.
  #9  
Old 12-08-2012, 06:14 PM
MrXXXnX
Guest
 
Posts: n/a
Default

Can we have some content-wise discussion about the subject? Because the thing would be interesting if there were some facts, code or something.

My humble guess also would be that you're posting a link to your own twitter profile Pablo to make it more popular since you have 0 posts here, otherwise I don't understand why someone suddenly came here, registered and posted this.
  #10  
Old 12-08-2012, 06:22 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by puertoblack2003 View Post
vbulletin has nothing to do with exploits. It's server side. I remember reading it somewhere.
There can be some exploits installed via bad skins for example, and some after market mods leave security holes and cause risk. A "exploit" is any entry point for everything from script kiddies to hard core black hat hackers.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:20 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04685 seconds
  • Memory Usage 2,265KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (7)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (7)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (3)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (7)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • postbit_imicons
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete